MEDIUM✓ PATCH🇬🇧 English

CVE-2026-21528

CVSS 6.5v3.1pub. 2026-02-10upd. 2026-02-19

Powiązanie się z nieograniczonym adresem IP w Azure IoT Explorer pozwala nieautoryzowanemu atakującemu na ujawnienie informacji przez sieć.

Pokaż oryginał (EN)

Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Microsoft Azure Iot Explorer

    APP
    Microsoft
    < 0.15.13
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-23661HIGH7.5ten sam produkt

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to discl...

CVE-2026-23662HIGH7.5ten sam produkt

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose...

CVE-2026-23664HIGH7.5ten sam produkt

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthoriz...

CVE-2026-26121HIGH7.5ten sam produkt

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing o...

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓ten sam vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint